PT-2023-21871 · Nextcloud · Nextcloud Android App
Nickvergessen
·
Publicado
2023-03-30
·
Atualizado
2023-04-07
·
CVE-2023-28646
CVSS v3.1
4.4
Média
| Vetor | AV:P/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Nextcloud Android versions 3.7.0 through 3.24.0
Description
The Nextcloud Android app has a security issue that allows an attacker with access to an unlocked physical device to bypass the Pin/passcode protection using a third-party app. This enables the attacker to view meta information such as sharer, sharees, and activity of files.
Recommendations
For versions 3.7.0 through 3.24.0, upgrade the Nextcloud Android app to version 3.24.1 to resolve the issue.
Exploit
Correção
Improper Preservation of Permissions
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Nextcloud Android App